Skip to main content

WordPress Multiple Vulnerabilities

Release Date: 20 Jul 2026 1683 Views

RISK: High Risk

TYPE: Servers - Internet App Servers

TYPE: Internet App Servers

Multiple vulnerabilities were identified in WordPress. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution,  sensitive information disclosure and data manipulation on the targeted system.

 

Note:

Proof-of-concept code is publicly available for CVE-2026-63030 and CVE-2026-60137. Attacker can be chained together to achieve pre-authentication remote code execution against WordPress installs running versions 6.9.x and 7.0.x.


Impact

  • Remote Code Execution
  • Information Disclosure
  • Data Manipulation

System / Technologies affected

  • WordPress 6.8
  • WordPress 6.9
  • WordPress 7.1

Please refer to the link below:

https://wordpress.org/news/2026/07/wordpress-7-0-2-release/


Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:

 

https://wordpress.org/news/2026/07/wordpress-7-0-2-release/


Vulnerability Identifier


Source


Related Link